Splunk Enterprise

Restart of Splunk Agent using script

nvnbsibm
New Member

Hi All,

 

We are looking for a script to restart the splunk agent when ever it gets stopped could you please help us if anyone has any script to restart it on both linux & windows servers

 

THanks in Advance

Labels (1)
0 Karma

SinghK
Builder

On windows you don't need a script in services.msc there is an option for each sevice to recover if it stops there 3 actions u can define for first faliure second faliure and 3rd faliure. You can use that to auto restart and this can be pushed to all windows server as well as it's oob function in wimdows

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Firstly, if your forwarder crashes often, you should look for the cause.

Secondly - I'm not that proficient with windows services but with linux you can either use a solution that monitors and restarts service if needed if you're not using systemd (like monit). If you're using sysyemd, the unit file is written so that the service does restart in case of a crash. See https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/RunSplunkassystemdservice#Configure_systemd...

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

I totally agree with @PickleRick that if there are more than few crashes / stops on splunkd you should resolve the reason and fix it.

To restart splunkd in linux you should use systemd and in windows just configure service for restarting it after crash/stop. Then on both environment you should have some monitoring which are looking that those are running and if automation cannot restart those you must check those manually and find the reason why automation cannot bring services up.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...